Protect.Computer
NEWS

Attackers Exploit Rejetto HFS Flaw CVE-2026-61500

· 1 min read · Got hacked Network safety
Attackers Exploit Rejetto HFS Flaw CVE-2026-61500

VulnCheck reports active exploitation attempts against CVE-2026-61500 (CVSS 9.3), a session-forgery flaw in Rejetto HTTP File Server (HFS). The bug is a weak-randomness problem: HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from JavaScript’s non-cryptographic Math.random() and exposes outputs of the same generator to unauthenticated clients during the login handshake. An attacker who collects a small number of login responses can reconstruct the generator’s state, recover the signing key and forge an administrator session cookie. From there, HFS’s server_code configuration feature, which allows custom endpoints that run arbitrary JavaScript, gives a direct path to remote code execution.

A fix shipped in HFS 3.2.1 in July 2026, but a public Python proof-of-concept only appeared in late September. Horizon3.ai published details on September 30 and said Anthropic’s Mythos model was used to find the flaw. VulnCheck saw exploitation attempts begin on October 1, a day after the Horizon3.ai write-up, and said an unnamed threat actor in China was targeting real vulnerable hosts in the U.S. It is the second Rejetto HFS vulnerability to be exploited in the wild, after CVE-2024-23692 in 2024.

How to check if you’re affected

Affected versions are Rejetto HFS 3.0.0 through 3.2.0. Check the version shown in your HFS admin panel or the release you installed; anything in that range should be upgraded to 3.2.1 or later. Affected products include any internet-facing HFS server, so if you cannot update right away, take the server off the public internet. If you cannot rule out exposure, review the server_code configuration and the admin accounts and sessions on the server for changes you did not make.

Sources

Related reading